CVE-2025-62242: Medium severity Liferay portal vulnerability
Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different account via the comliferayaccountadminwebinternalportletAccountEntriesAdminPortletaddressId parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62242?
CVE-2025-62242 has been classified as a medium severity vulnerability due to its exploitation potential in sensitive account information exposure.
How do I fix CVE-2025-62242?
To fix CVE-2025-62242, upgrade Liferay Portal to version 7.4.3.112 or later and Liferay DXP to 2023.Q4.6 or later.
What type of vulnerability is CVE-2025-62242?
CVE-2025-62242 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
Who is affected by CVE-2025-62242?
CVE-2025-62242 affects users of Liferay Portal versions 7.4.3.4 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5.
Can CVE-2025-62242 be exploited remotely?
Yes, CVE-2025-62242 can be exploited by remote authenticated users to improperly access other users' account addresses.